Yea sorry, I thought that was the "old" code. I was thinking EC crypto, since that's much, much faster on slow hardware. It surprised me a bit when I started experimenting, but given the much shorter keys it actually makes some sense.
See
https://git.anduin.net/ltning/sshbench - I have not tested on anything slower than a crappy 486 (because no modern BSD will work on any of them) but EC ciphers generally come out on top every time - by a huge margin, too.